I building a central ELK stack that will be used to aggregate the logs from different customer installations, with each installation having multiple servers. I use rsyslog as the shipper. I wan to be able to "see" the following example structure in my ELK server
I started reading about rsyslog templates but am not making the connection yet. For example, how can I embed the "Custoer name" and "Server name" information in the log, and then how can Logstash extract that information?
If rsyslog knows the customer name it should be easy to include it as (for example) a prefix of each message. Logstash can then extract the customer name along with the hostname, timestamp, and whatever else you've got.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.